<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securing console from single user boot in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826205#M754753</link>
    <description>Wow, many responses, much appreciated.&lt;BR /&gt;&lt;BR /&gt;One comment, these are workstations on desks, the console is a 21??? monitor the user uses, so I can???t turn it off.&lt;BR /&gt;</description>
    <pubDate>Tue, 15 Oct 2002 15:45:25 GMT</pubDate>
    <dc:creator>Alan Edwards</dc:creator>
    <dc:date>2002-10-15T15:45:25Z</dc:date>
    <item>
      <title>Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826199#M754747</link>
      <description>Is it possible to secure the console from booting into single user mode unless you know the root password?&lt;BR /&gt;&lt;BR /&gt;The specific systems I am using are J series workstations.&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Oct 2002 15:27:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826199#M754747</guid>
      <dc:creator>Alan Edwards</dc:creator>
      <dc:date>2002-10-15T15:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826200#M754748</link>
      <description>It is not possible to secure the single user boot-up. Because when you boot up in single user mode it does not ask for any password.&lt;BR /&gt;&lt;BR /&gt;Sandip</description>
      <pubDate>Tue, 15 Oct 2002 15:33:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826200#M754748</guid>
      <dc:creator>Sandip Ghosh</dc:creator>
      <dc:date>2002-10-15T15:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826201#M754749</link>
      <description>I am not sure if this is compatible... but it is certainly something that may be worth looking into.  You could get rid of the "local" console and replace with a web console.  To access the console you can configure an additional log-in with password.  Not fool proof, as someone could hook up a local monitor and reboot the box anyway, but it makes it more difficult... and nice to have that web-console for remote operations... something to consider&lt;BR /&gt;&lt;BR /&gt;Ted</description>
      <pubDate>Tue, 15 Oct 2002 15:36:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826201#M754749</guid>
      <dc:creator>Ted Ellis_2</dc:creator>
      <dc:date>2002-10-15T15:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826202#M754750</link>
      <description>Only if you convert your workstation to truted mode. With trusted you can configure (in SAM) it in such a way that when the system boots up in single user mode a login is required. Typically when booting the system in single user mode you'll see something like "boot authentication" required (kindda like a login prompt).</description>
      <pubDate>Tue, 15 Oct 2002 15:37:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826202#M754750</guid>
      <dc:creator>S.K. Chan</dc:creator>
      <dc:date>2002-10-15T15:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826203#M754751</link>
      <description>Actually, there is a way to secure single user mode: convert to a Trusted System. One of the policies in Trusted is to require root password to get a shell prompt.&lt;BR /&gt;&lt;BR /&gt;Otherwise, to secure the system from single user mode attacks, the computer and (all) console access must be physically protected with locked doors, etc.</description>
      <pubDate>Tue, 15 Oct 2002 15:37:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826203#M754751</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2002-10-15T15:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826204#M754752</link>
      <description>I know; that is why I am asking.  In the back of my mind I remember an HP reference to a "Secure Console boot".&lt;BR /&gt;&lt;BR /&gt;This can be done on other UNIX's, for example Linux.  If HP cannot, is a security hole as workstations are typically on a desk, not in a secure computer room.&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Oct 2002 15:43:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826204#M754752</guid>
      <dc:creator>Alan Edwards</dc:creator>
      <dc:date>2002-10-15T15:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826205#M754753</link>
      <description>Wow, many responses, much appreciated.&lt;BR /&gt;&lt;BR /&gt;One comment, these are workstations on desks, the console is a 21??? monitor the user uses, so I can???t turn it off.&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Oct 2002 15:45:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826205#M754753</guid>
      <dc:creator>Alan Edwards</dc:creator>
      <dc:date>2002-10-15T15:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826206#M754754</link>
      <description>We had quite an extensive discusson back in May. You may want to read this ..&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x6c118f960573d611abdb0090277a778c,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x6c118f960573d611abdb0090277a778c,00.html&lt;/A&gt;</description>
      <pubDate>Tue, 15 Oct 2002 15:49:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826206#M754754</guid>
      <dc:creator>S.K. Chan</dc:creator>
      <dc:date>2002-10-15T15:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826207#M754755</link>
      <description>I'm not sure I can do trusted mode, we use NIS for user authentication.</description>
      <pubDate>Tue, 15 Oct 2002 15:50:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826207#M754755</guid>
      <dc:creator>Alan Edwards</dc:creator>
      <dc:date>2002-10-15T15:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826208#M754756</link>
      <description>Correct. NIS defeats the whole purpose of a Trusted system by sending the encrypted password across the network. A Trusted system uses a shadow password technique. There is an NIS+ standard which does provide encryption for the commuinication but it is totally incompatible with plain NIS, thus all clients must support NIS+ before switching.&lt;BR /&gt;&lt;BR /&gt;Workstations are always a problem due to lack of physical security. The night crew that cleans the floor is a perfect cover to tap on keyboards when no one is looking. The best way to secure the data is over the network. The screen lockout prevents access in multiuser mode, and in single user mode, it is impossible to do any networking. Of course, NFS brings it's own set of problems...</description>
      <pubDate>Tue, 15 Oct 2002 17:01:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826208#M754756</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2002-10-15T17:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826209#M754757</link>
      <description>Hi Bill, I agree, there is not much that can be done.&lt;BR /&gt;&lt;BR /&gt;After rethinking this, I don???t think this is a problem that needs fixing after all.  We do have all user data and applications on NFS or AFS shares, so there isn't anything locally.&lt;BR /&gt;&lt;BR /&gt;If someone did bring a system to single user mode they couldn???t get to anything on the network, and I can re-ignite the system in 45 minutes.&lt;BR /&gt;&lt;BR /&gt;Thanks, everybody&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Oct 2002 17:39:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826209#M754757</guid>
      <dc:creator>Alan Edwards</dc:creator>
      <dc:date>2002-10-15T17:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Securing console from single user boot</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826210#M754758</link>
      <description>Hi,&lt;BR /&gt;I'm not so sure about the security. True, that you can't access the network in single user mode, but what hinders you to choose files first in the nsswitch.conf (before NIS) and change the root password. Then you could execute an init 4 login as root and su to any user you want (Though I'm not 100% sure if NIS allows this) and open up  a NFS connection this user is allowed to.&lt;BR /&gt;I think there was a switch in the boot menu that allowed to disable the interuption of the bootup. though I don't really know if the J-Class still has something like this and it would also be not 100% sure.&lt;BR /&gt;Hope it helped.</description>
      <pubDate>Wed, 16 Oct 2002 13:51:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-console-from-single-user-boot/m-p/2826210#M754758</guid>
      <dc:creator>Steffen Jaiser</dc:creator>
      <dc:date>2002-10-16T13:51:40Z</dc:date>
    </item>
  </channel>
</rss>

